workflow

CSF 2.0 Profile & Maturity Assessment

Runs on an Audit item created for this assessment cycle (audit_type = readiness) — the CSF assessment engagement the workflow instance attaches to and enriches as it progresses (scope, period, rating, and report fields are written on that Audit item; every in-scope Control is linked to it so the controls-scoped profile is queryable). Build, against that boundary, a NIST CSF 2.0 Current Profile, a Target Profile, an organizational Tier rating, a subcategory gap analysis, and a CISO-ready remediation roadmap. The workflow originates on its own — scoping ingests prior CSF profiles and open POA&M (Issue) items as data, not as a named upstream handoff. In scope: rating the in-scope control set against the CSF 2.0 Core, setting target outcomes, assigning a Tier, and producing a prioritized roadmap. Out of scope: executing the remediation projects themselves and re-performing independent assurance testing. The named deliverable is the assessment package (profiles, gap analysis, Tier, posture report, roadmap, closure artifact), handed off to TWO downstream workflows that consume it rather than repeat the profiling: the Cybersecurity Assurance Review (always) and the AI Governance & Risk/Impact Assessment (only when AI systems fall inside the boundary).

Record JSON · Open in map · Data retrieval guide

Catalog revision: f368a6cce277037e4b1e1ff46004e3acd295f96c9ac63a411a0e45775a7f468e. A connection does not establish full coverage.

Attributes

domain
controls
department
it
lineOfDefense
monitor

Details

teams
  • it
  • executive
domains
  • controls
standards
  • nist-csf-2
sourceTemplateId
workflow-library:controls-csf-profile-maturity-assessment
releaseId
sha256:03ada8978d8269bca766c98346e0616c11aa6b1a30ff0026f3dfd2bc7c84a08e
canonicalUrl
https://assureswarm.com/workflows/all/?w=controls-csf-profile-maturity-assessment
capabilities
    mappingStatus
    mapped
    lineOfDefense
    monitor
    controls
    • UC-AUDIT-22
    • UC-RISK-13
    • UC-RISK-14
    • UC-GOV-02
    • UC-GOV-04
    • UC-GOV-06
    • UC-GOV-09
    • UC-GOV-10
    • UC-GOV-11
    • UC-GOV-12
    • UC-TPRM-01
    • UC-RISK-15
    roleIntegrity
    activityCount
    0
    ermPhases
      lineRoles
        serviceModes
          warnings

            Source

            No record-specific source URL is provided.

            Download workflow template · Release: sha256:03ada8978d8269bca766c98346e0616c11aa6b1a30ff0026f3dfd2bc7c84a08e

            Connections